Links, proof statistics please ?
I think you also need to differentiate between servers and desktops. There are a hell of a lot more compromised desktop machines which are Windows - mainly because they are more popular, but also due to the distinct differences between Linux and Windows (some which Vista should address).
There are far more Linux severs on the web, which are badly protected - or incorrectly setup, hence they become zombies.
An OS is only as secure as the knowledge and ability of the operator in my opinion, far too many people see the 'free web hosting' 'cheap web hosting' stick a forum or website on there and just leave it without ensuring the forum software is fully patched. For those with their own servers, it is amazing how many SSH password guessing attempts are actually successful because the operator of that server has left their password as 'admin'
Ok rant over